phpmyadmin -- arbitrary file include and XSS vulnerabilities

Description:

We received two bug reports by Maksymilian Arciemowicz
about those vulnerabilities and we wish to thank him for
his work. The vulnerabilities apply to those points:

css/phpmyadmin.css.php was vulnerable against
$cfg and GLOBALS variable
injections. This way, a possible attacker could
manipulate any configuration parameter. Using
phpMyAdmin's theming mechanism, he was able to include
arbitrary files. This is especially dangerous if php is
not running in safe mode.

A possible attacker could manipulate phpMyAdmin's
localized strings via the URL and inject harmful
JavaScript code this way, which could be used for XSS
attacks.

Affects:

Disclaimer: The data contained on this page is derived from the VuXML document,
please refer to the the original document for copyright information. The author of
portaudit makes no claim of authorship or ownership of any of the information contained herein.